CVE-2020-6207 is a critical authentication bypass vulnerability in the End-user Experience Monitoring (EEM) application of SAP Solution Manager (SolMan) version 7.2. The EEM service fails to enforce authentication, allowing unauthenticated attackers with network access to the SolMan web server to interact with the service. Attackers can upload and execute custom scripts, abuse SSRF, and leverage unsanitized JavaScript evaluation for remote code execution as the daaadm user. When chained with privilege escalation flaws in the SAP Host Agent (CVE-2020-6234, CVE-2020-6236), this enables unauthenticated attackers to gain root/system access across all SAP servers connected to the Solution Manager, leading to full landscape compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting CVE-2020-6207, a critical unauthenticated remote code execution vulnerability in SAP Solution Manager (SolMan) version 7.2. The exploit abuses missing authentication in the EEM servlet's SOAP interface (/EemAdminService/EemAdmin) to execute arbitrary OS commands on connected SMDAgents. The module supports both Linux and Windows targets and leverages Metasploit's command stager to deliver payloads, typically resulting in a reverse shell as the SMDAgent service user. The exploit requires network access to the SolMan system (default port 50000) and knowledge of a connected agent's name. The code is operational and weaponized for use within the Metasploit framework, with options to specify the target URI, port, and agent name. The repository is well-structured, containing only the exploit module, and is intended for penetration testers or red teamers targeting vulnerable SAP Solution Manager deployments.
This repository contains a single Metasploit auxiliary module targeting CVE-2020-6207, a critical unauthenticated remote code execution vulnerability in SAP Solution Manager (SolMan) version 7.2. The exploit abuses missing authentication in the EEM servlet (/EemAdminService/EemAdmin) to perform several actions: listing connected SMDAgents, sending SSRF requests from the agent, executing arbitrary OS commands on the agent, and exfiltrating credential files via HTTP callbacks. The module is highly weaponized, supporting multiple attack actions and customizable payloads. It is written in Ruby and leverages Metasploit's HTTP client/server mixins. The main fingerprintable endpoint is the EEM servlet path, with additional configuration options for SSRF and callback IPs. The exploit is operational and can be used to gain remote code execution as the SMDAgent user (typically 'daaadm') on affected SAP Solution Manager installations.
This repository provides a working exploit for CVE-2020-6207, a critical unauthenticated remote code execution vulnerability in SAP Solution Manager's EEM servlet. The main exploit script, 'sol-rce.py', is a Python3 tool that interacts with the vulnerable SOAP endpoint '/EemAdminService/EemAdmin' on the target SAP Solution Manager instance. The script supports multiple attack modes: checking for vulnerability, executing arbitrary commands (RCE), SSRF, and establishing reverse shells (backconnect). It does so by crafting and sending SOAP/XML payloads that abuse the lack of authentication on the EEM admin interface, allowing the attacker to upload and execute scripts on connected SMDAgents. The repository also includes a Snort detection rules file ('detect.rules') for network defenders, and detailed exploitation steps and background in 'Process.md'. The exploit is operational, not just a PoC, as it provides working payloads and automation for exploitation. No authentication is required, and exploitation is possible over the network if the endpoint is exposed. The repository targets SAP Solution Manager installations prior to the fix in SAP Note 2890213.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.